# BVwG - W292 2292202-1

- Type: Case Law
- Source: Federal Administrative Court
- Date: 2026-06-30
- Original: https://gdprhub.eu/index.php?title=BVwG_-_W292_2292202-1
- Canonical: https://overview.legal/posts/353789
- Topics: Supervision, Controllers, Personal Data, Special Categories of Data, Supervisory Authorities, Health Data, Types of Special Categories of Personal Data, Healthcare, Processing, Professional Secrecy

## Summary

Facts — The data subject is in the military. The unit he is employed at (controller) and the data subject are involved in a multitude of legal disputes concerning his employment, disciplinary proceedings, data protection matters as well as procedures of criminal law. After the controller revealed information on one of the legal proceedings concerning a penalty he received in an official meeting to third persons, the data subject lodged a complaint with the DPA. In the course of the DPA investigation of the complaint, the controller revealed to the DPA a statement written by the data subject concerning his declining health status because of the multitude of proceedings between the two parties. The data subject considered the sharing of this document as a processing of health data, in violation of Article 9 GDPR. The proceeding before the DPA dealt with the question of whether the data subject’s complaint was excessive pursuant to Article 57(4) GDPR. The DPA held that the statement constituted health data pursuant to Article 4(15) GDPR. Since the processing of the statement happened in the context of the enforcement of legal claims, the DPA did not find a violation of Article 9 GDPR. The data subject appealed the DPA's decision. Holding — The Court upheld the DPA’S decision and decided that the controller could rely on the legal basis of Article 9(2)(f) GDPR. The Court held that the notion of “legal claims” pursuant to Article 9(2)(f) GDPR must be understood broadly as meaning any legal conflict. The notion of necessity in the context of Article 9(2)(f) GDPR is to be applied broadly as well because of the role the exemption plays for the enforcement of legal claims and because of Article 47 CFR, the right to an effective remedy and fair trial. “Necessary” must be understood as meaning that without the data in question, the enforcement of legal claims must be impossible or considerably more difficult. According to the Court, the requirement of necessity is not met where the processing of health data is arbitrary and bears no connection to the legal proceeding. This question must be assessed from an ex-ante perspective. For the case at hand, the Court decided, that the statement concerning the data subject’s health data was lawfully shared with the DPA. This is because the DPA had to decide on the question of whether the data subject’s complaint was excessive pursuant to Article 57(4) GDPR. In order for the DPA to answer this legal question, it is necessary for the DPA to receive all information on the multitude of legal disputes between the parties to get an understanding of the situation, and the statement is part of the correspondence between the parties on their disputes. Moreover, since the DPA is obliged to treat the information it receives confidentially, a higher level of protection of health data is guaranteed. According to the Court, the data subject deserves less protection because he made the statement available to the controller himself.

## Full text

Date of Decision June 30, 2026 Legal Provisions B-VG Art. 133(4) DSG §1 DSG §24 GDPR Art. 4(1) GDPR Art. 4(15) GDPR Art. 4(2) GDPR Art. 5(1) GDPR Art. 6(1)(f) GDPR Art. 9(2)(f) B-VG Art. 133 (current version); B-VG Art. 133 effective from Jan. 1, 2019, to May 24, 2018, last amended by BGBl. I No. 138/2017 Federal Constitutional Law (B-VG) Art. 133 effective as of January 1, 2019, last amended by Federal Law Gazette (BGBl.) I No. 22/2018 Federal Constitutional Law (B-VG) Art. 133 effective from May 25,May 2018 through December 31, 2018; last amended by Federal Law Gazette I No. 22/2018; B-VG Art. 133; effective from August 1, 2014, through May 24,2018, last amended by Federal Law Gazette I No. 164/2013, B-VG Art. 133, effective from January 1, 2014, through July 31, 2014, last amended by Federal Law Gazette I No. 51/2012 Federal Constitutional Law (B-VG) Art. 133, effective from January 1, 2004, through December 31, 2013, last amended by Federal Law Gazette (BGBl.) I No. 100/2003 B-VG Art. 133 effective from January 1, 1975, through December 31, 2003, last amended by Federal Law Gazette No. 444/1974 B-VG Art. 133 valid from Dec. 25, 1946, through Dec. 31, 1974, last amended by Federal Law Gazette No. 211/1946 B-VG Art. 133 valid from Dec. 19,December 1945 through December 24, 1946; last amended by State Law Gazette No. 4/1945; B-VG Art. 133; in effect from January 3, 1930, through June 30, 1934 DSG Art. 1 § 1 (now DSG Art. 1 § 1), effective as of Jan. 1, 2014, last amended by Federal Law Gazette I No. 51/2012 DSG Art. 1 § 1 valid from Jan. 1, 2000, through Dec. 31, 2013 DSG Art. 2 § 24 (currently DSG Art. 2 § 24), effective as of July 15, 2024, last amended by Federal Law Gazette I No. 70/2024; DSG Art. 2 § 24 was effective from May 25,May 2018 through July 14, 2024; last amended by Federal Law Gazette I No. 120/2017 DSG Art. 2 § 24 valid from January 1, 2010, through May 24,2018, last amended by Federal Law Gazette I No. 133/2009, DSG Art. 2 § 24, effective from Jan. 1, 2000, through Dec. 31, 2009 Judgment , W292 2292202-1/5E W292 2292202-1/5E, IN THE NAME OF THE REPUBLIC! The Federal Administrative Court, with Judge Mag. Herwig ZACZEK presiding and lay judges Mag. René BOGENDORFER and Mag. Matthias SCHACHNER serving as associate judges, has ruled on the complaint filed by XXXX against the decision of the Data Protection Authority dated XXXX, XXXX (intervening party: Army Troop School Command, represented by the Federal Minister of Defense, Roßauer Lände 1, 1090 Vienna), in a matter concerning data protection law, has rightly ruled: The Federal Administrative Court, presided over by Judge Mag. Herwig ZACZEK as presiding judge and the lay judges with expertise in the field, Mag. René BOGENDORFER and Mag. Matthias SCHACHNER as associate judges, regarding the complaint filed by Roman numeral 40 against the decision of the Data Protection Authority dated Roman numeral 40, Roman numeral 40 (intervening party: Army Troop School Command, represented by the Federal Minister of Defense, Roßauer Lände 1, 1090 Vienna), in a matter concerning data protection, has ruled as follows: A) The complaint is dismissed as unfounded pursuant to Art. 5(1), Art. 6(1)(f), and Art. 9(2)(f) of the GDPR.The complaint is dismissed as unfounded pursuant to article 5, paragraph 1, article 6, paragraph 1, subparagraph f, and article 9, paragraph 2, subparagraph f, of the GDPR. The appeal is not admissible pursuant to Article 133(4) of the Federal Constitutional Law (B-VG). The appeal is not admissible pursuant to Article 133(4) of the Federal Constitutional Law (B-VG). Text Reasons for the Decision: I. Course of Proceedings: Roman numeral I. Course of Proceedings: 1. In a petition dated July 19, 2023, addressed to the Data Protection Authority (hereinafter: “Respondent”), XXXX (the complainant in the proceedings before the Respondent and in the present proceedings; hereinafter: complainant), a data protection complaint against the Command of the Army Training School of the Federal Ministry of Defense (hereinafter: “co-party”) regarding an alleged violation of the right to confidentiality; Accordingly, in the proceedings concerning XXXX already pending before the respondent authority, the co-party disclosed to the respondent authority information regarding criminal proceedings, data concerning the complainant’s health, and his private email address. The sole issue in these proceedings is whether employees of the Army Training School in Eisenstadt unlawfully disclosed information relating to the complainant’s disciplinary proceedings, which have not yet become final. However, the sensitive personal data (data concerning health) of the complainant now disclosed by the intervening party, as well as his criminal record (voluntary disclosure) and his private email address disclosed by the intervening party are, however, irrelevant to the respondent authority’s decision-making in the aforementioned proceedings; therefore, their disclosure also constitutes a violation of Article 5 of the GDPR. Nor can Article 9(2)(f) of the GDPR be invoked.1. In a request dated July 19, 2023, addressed to the Data Protection Authority (hereinafter: the respondent authority), the complainant, Roman 40, filed a data protection complaint in the proceedings before the respondent authority and in the present proceedings, hereinafter: complainant), a data protection complaint against the Command of the Army Troop School of the Federal Ministry of Defense (hereinafter: “co-party”) regarding an alleged violation of the right to confidentiality; According to the complaint, in the proceedings already pending before the respondent authority regarding Roman 40, the co-party disclosed to the respondent authority information regarding criminal proceedings, data concerning the complainant’s health, and his private email address. The sole issue in these proceedings is whether employees of the Eisenstadt Army Troop School unlawfully disclosed information relating to his non-final disciplinary proceedings. However, the sensitive personal data (data concerning health) of the complainant, as well as his criminal record (voluntary disclosure) and his private email address have no relevance to the decision-making process of the respondent authority in the aforementioned proceedings; therefore, their disclosure also violates Article 5 of the GDPR. Nor can article 9(2)(f) of the GDPR be invoked. 2. The co-party (specifically, the Data Protection Office as the legal representative of the co-party) submitted a statement in response to a corresponding official request in a written submission dated August 11, 2023. In it, the co-party noted that, based on the current division of responsibilities for the Central Office of the Federal Ministry of National Defense, the Data Protection Office performs the duties (and exercises the rights) of the co-party in the proceedings in question. As to the substance, the co-party pointed out that the data protection complaint relates exclusively to proceedings in the XXXX case, which is why reference is also made to the co-party’s previous statements in these proceedings—specifically those dated June 29, 2023, July 4, 2023, and August 1, 2023, along with the supporting documents attached thereto, should be taken into account. As already explained in detail therein, the reference to the proceedings before the respondent authority regarding XXXX—in the course of which the alleged transfer of the disputed criminal data also took place —what was necessary in order to present the complainant’s arguments in this regard within the relevant overall context (chronologically), as a prerequisite for a proper assessment under data protection law within the meaning of para 1 of the Data Protection Act (DSG). This was also necessary to objectively assess the view represented by the BMLV that the complainant’s conduct of the proceedings before the Data Protection Authority was excessive within the meaning of Art. 57(4) of the GDPR. In summary, both the transfer of the data to the Data Protection Office and the subsequent transfer from the Data Protection Office to the respondent authority were necessary and lawful. As to the substance, the co-party pointed out that the data protection complaint relates exclusively to events in the proceedings concerning Roman numeral 40, which is why reference should also be made to the co-party’s statements already issued in these proceedings, specifically those dated June 29, 2023, July 4, 2023, and August 1, 2023, along with the supporting documents attached thereto. As already explained in detail therein, the reference to the proceedings before the respondent authority regarding Roman numeral 40—in the course of which the alleged transfer of the disputed criminal data also took place—was necessary in order to present the complainant’s arguments in this regard in the relevant overall context (chronologically), as a prerequisite for a proper assessment under data protection law within the meaning of Section 1, paragraph 1, of the Data Protection Act (DSG), to present the complainant’s arguments in this regard within the relevant overall context (chronologically). This was also necessary to objectively assess the BMLV’s representation that the complainant’s conduct of the proceedings before the Data Protection Authority was excessive within the meaning of article 57, paragraph 4, of the GDPR. In summary, both the transfer of the data to the Data Protection Office and the subsequent transfer from the Data Protection Office to the authority in question were necessary and lawful. In summary, the complainant’s petitions to the Data Protection Authority regularly pursue the goal of alleging misconduct on the part of his superiors that is subject to disciplinary action, thereby seeking to undermine their credibility in the disciplinary proceedings [conducted against him]. 4. Following further reply briefs, the complainant filed a complaint for failure to act with the respondent authority on January 28, 2023, in the administrative matter at hand, pursuant to Art. 130(1)(3) of the Federal Constitutional Law (B-VG).4. Following further reply briefs, the complainant filed a complaint for failure to act with the respondent authority on January 28, 2023, in the administrative matter at hand, pursuant to article 130, paragraph 1, item 3, of the Federal Constitutional Law (B-VG). 5. By decision dated April 23, 2024, the respondent authority discontinued the complaint for failure to act, as it had subsequently issued the decision numbered XXXX—thereby acting within three months of receiving the complaint for failure to act.5. By decision dated April 23, 2024, the respondent authority discontinued the complaint for failure to act, as it had subsequently issued the decision numbered XXXX—thereby doing so within three months of the receipt of the complaint for failure to act. 6. In the decision dated XXXX, which is the subject of this proceeding, the Data Protection Authority dismissed the complainant’s data protection complaint. In its reasoning, the respondent authority—insofar as it is still relevant to the present complaint proceedings—states that the voluntary disclosure in question does not constitute data related to criminal law. However, since all data processing requires a legal basis, Art. 6(1) of the GDPR or § 1(2) of the DSG must be considered. Regarding the complainant’s argument that the respondent authority failed to utilize the information provided in the context of the statement of facts or evaluation of evidence, the respondent authority refers to the conduct of a preliminary investigation in accordance with the rule of law, within the framework of which the processing of all personal data that could conceivably be suitable for a complete investigation of the facts relevant to the decision is permissible. The information in question is therefore at least indirectly related to the disciplinary decision concerning the complainant that is the subject of the complaint. In addition, there is also a (prevailing) interest on the part of the co-party itself; it has a legitimate interest in a decision by the Data Protection Authority that is favorable to it and, in this context, is entitled to present everything that is (conceivably) advantageous to it before the Data Protection Authority and to offer evidence supporting its position in the proceedings. Furthermore, the co-party, in its capacity as a controller, is subject to comprehensive obligations to cooperate before the Data Protection Authority; against this background, all information necessary for the Data Protection Authority to fulfill its duties must be provided to it, and a lack of cooperation could also result in procedural disadvantages for the co-party. 6. In the decision at issue here, dated Roman numeral 40, the Data Protection Authority dismissed the complainant’s data protection complaint. In its reasoning, the respondent authority—insofar as it is still relevant to the present complaint proceedings—states that the voluntary disclosure in question does not constitute data related to criminal law. However, since all data processing requires a legal basis, article 6(1) of the GDPR and paragraph 1(2) of the DSG must be considered. Regarding the complainant’s argument that the respondent authority failed to use the information provided in the statement of facts or evaluation of the evidence, the respondent authority points to the conduct of a preliminary investigation in accordance with the rule of law, within the framework of which the processing of all personal data that could conceivably be suitable for the complete investigation of the facts relevant to the decision is permissible. The information in question is therefore at least indirectly related to the disciplinary decision concerning the complainant that is the subject of the complaint. In addition, there is also a (prevailing) interest on the part of the co-party itself; it has a legitimate interest in a decision by the Data Protection Authority that is favorable to it and, in this context, is entitled to present all arguments that are (conceivably) favorable to it before the Data Protection Authority and to offer evidence supporting its position in the proceedings. Furthermore, the co-party, in its capacity as a controller, is subject to comprehensive obligations to cooperate before the Data Protection Authority; against this background, all information necessary for the Data Protection Authority to fulfill its duties must be provided to it, and a lack of cooperation could also result in procedural disadvantages for the party involved. With regard to the contested transfer of data concerning health, the complainant’s position can be upheld to the extent that the data at issue in the proceedings constitutes data concerning health pursuant to Art. 4(15) GDPR; however, its processing must be regarded as justified (Article 9(2)(f) of the GDPR). With regard to the contested transfer of data concerning health, the complainant’s position can be upheld to the extent that the data at issue in the proceedings constitutes data concerning health pursuant to Article 4(15) GDPR; however, their processing is to be regarded as justified (article 9(2)(f) GDPR) in light of the above considerations. 8. In his appeal against this decision dated May 14, 2025, the complainant limits the scope of his challenge to the issue of the processing of his data concerning health. Accordingly, the processing of his data concerning health in the present context constitutes a violation of the processing principles set forth in Article 5 of the GDPR (“data minimisation”; it is inconceivable that the data concerning his health could have had any impact on the investigative proceedings aimed at clarifying whether a specific person had disclosed the disciplinary finding concerning him or not. 8. In his appeal against this decision dated May 14, 2025, the complainant limits the scope of the challenge to the issue of the processing of his data concerning health. Accordingly, the processing of his data concerning health in the present context constitutes a violation of the processing principles set forth in Article 5 of the GDPR (“data minimisation; it is inconceivable that the data concerning his health could have had any impact on the investigative proceedings aimed at clarifying whether a specific person had disclosed the disciplinary finding concerning him or not. II. The Federal Administrative Court considered: II. The Federal Administrative Court considered: 1. Findings: 1.1. The complainant is a civil servant in the military service employed by the Federal Government under public law and was most recently assigned to the Engineer Institute of the Austrian Armed Forces’ Army Troop School, an organizational unit of the co-party. 1.2. The co-party is an organizational unit of the Federal Ministry of Defense (Austrian Armed Forces Training Center) located at 7000 Eisenstadt, Ing. Hans Sylvester Street, and is the agency responsible for the complainant (at least at the time relevant to the proceedings). 1.3. Extensive legal disputes have existed between the complainant and the co-party for several years, manifesting themselves in proceedings under service and disciplinary law, data protection law, and criminal law. This circumstance is known to a large number of the respondent’s employees in varying degrees of detail. 1.4. On July 12, 2023, the complainant filed a data protection complaint pursuant to § 24 DSG in conjunction with Art. 77 GDPR with the respondent authority (XXXX). In it, the complainant alleged a violation of the right to confidentiality under § 1(1) of the Data Protection Act (DSG), in that, during an official meeting in March/April 2023, during an official meeting with members of his subordinate explosive ordnance disposal training group, the nature and severity of the penalty imposed by a non-final disciplinary decision concerning the complainant had been unlawfully disclosed by employees of the co-party. In a statement submitted by the co-party in these proceedings, a copy of the complainant’s written submission dated April 29, 2023, was provided to the authority under investigation, in which the complainant filed a complaint pursuant to § 13 ADV. This brief contains, among other things, the following statement by the complainant: 1.4. On July 12, 2023, the complainant filed a data protection complaint with the respondent authority pursuant to Section 24 of the DSG in conjunction with article 77 of the GDPR (Roman numeral 40). In it, the complainant alleged a violation of the right to confidentiality under Section 1, paragraph 1, of the Data Protection Act (DSG), in that during the period from March toApril 2023, during an official meeting with members of his subordinate explosive ordnance disposal training group, the nature and severity of the penalty imposed by a non-final disciplinary decision concerning the complainant had been unlawfully disclosed by employees of the co-respondent. In a statement submitted by the co-party during these proceedings, a copy of the complainant’s brief dated April 29, 2023, was provided to the respondent authority; in this brief, the complainant filed a complaint pursuant to Section 13 of the Administrative Procedure Act (ADV). This brief includes, among other things, the following statement by the complainant: “State of Health That, due to the numerous data breaches by HTS […], my state of health has been compromised, reported, and is known to the authorities. The fact that I am now also being deprived of the right to a personal hearing—which would clearly have been solely about how the harm caused by the data breach could be minimized and what measures have been taken to prevent such breaches in the future—further worsens my state of health […] 2. Assessment of the Evidence: 2.1. The findings regarding the complainant and his official duties, as well as the co-involved party, are derived from the uncontroversial contents of the case file and from the complaint proceedings concluded by the Federal Administrative Court’s decision of February 3, 2026, under case no. W292 2289550-1/19E, whereby the parties to the proceedings are in any case aware of the findings of that investigation. 2.2. The subject matter of the proceedings before the respondent authority under Ref. No. XXXX is derived from the corresponding statements made by the parties in the present proceedings. The content of the complainant’s brief dated April 29, 2023, which was forwarded to the respondent authority by the co-party in the proceedings under Ref. No. XXXX, is evident from a copy of this brief contained in the court file at issue (OZ 2). 2.2. The subject matter of the proceedings before the respondent authority under Ref. Roman numeral 40 is evident from the relevant statements made by the parties to the proceedings in the case at hand. The content of the complainant’s brief dated April 29, 2023, which was submitted by the co-party in the proceeding under Ref. Roman numeral 40 to the respondent authority, is evident from a copy of this brief contained in the court file at issue (OZ 2). 3. Legal Assessment: 3.1. Regarding Point A) – Dismissal of the Complaint: Since the subject matter of the complaint is a decision by the Data Protection Authority, the Senate has jurisdiction pursuant to § 27 of the Data Protection Act (DSG). Since the subject matter of the complaint is a decision by the Data Protection Authority, the Senate has jurisdiction pursuant to § 27 of the Data Protection Act (DSG). Applicable Law: The relevant provisions of the Federal Act on the Protection of Natural Persons with Regard to the Processing of Personal Data (Data Protection Act—DSG), as amended by Federal Law Gazette I No. 50/2025, read as follows, including the heading:The relevant provisions of the Federal Act on the Protection of Natural Persons with Regard to the Processing of Personal Data (Data Protection Act—DSG), as amended by Federal Law Gazette Part I, No. 50 of 2025, read as follows, including the heading: Fundamental Right to Data Protection “§ 1. (1) Every person has the right, in particular with regard to respect for his or her private and family life, to the confidentiality of personal data concerning him or her, to the extent that there is a legitimate interest therein. The existence of such an interest is excluded if data are not subject to a right to confidentiality due to their general availability or because they cannot be traced back to the data subject. (2) To the extent that the use of personal data is not in the vital interest of the data subject or does not occur with the data subject’s consent, restrictions on the right to confidentiality are permissible only to safeguard the overriding legitimate interests of another, and, in the case of interventions by a government authority, only on the basis of laws that are necessary for the reasons set forth in Article 8(2) of the European Convention for the Protection of Human Rights and Fundamental Freedoms (ECHR), Federal Law Gazette No. 210/1958. Such laws may provide for the use of data that, by its Art, is particularly worthy of protection only to safeguard important public interests and must, at the same time, establish adequate safeguards for the protection of the privacy interests of the individuals concerned. Even in the case of permissible restrictions, the interference with the fundamental right must in each instance be carried out in the least intrusive Art necessary to achieve the objective. (2) To the extent that the use of personal data is not in the vital interest of the data subject or does not occur with the data subject’s consent, restrictions on the right to confidentiality are permissible only to safeguard the overriding legitimate interests of another party; in the case of interventions by a government authority, such restrictions are permissible only on the basis of laws that are necessary for the reasons set forth in article 8, paragraph 2, of the European Convention for the Protection of Human Rights and Fundamental Freedoms (ECHR), Federal Law Gazette No. 210 of 1958. Such laws may provide for the use of data that is, by its Art, particularly worthy of protection only to safeguard important public interests and must, at the same time, establish appropriate safeguards for the protection of the data subjects’ interests in confidentiality. Even in the case of permissible restrictions, the interference with the fundamental right may only be carried out in the least intrusive Art necessary to achieve the objective. […] Complaint to the Data Protection Authority § 24. (1) Every data subject has the right to lodge a complaint with the Data Protection Authority if they believe that the processing of their personal data violates the GDPR or § 1 or Article 2, Section 1. Paragraph 24, (1) Every data subject has the right to lodge a complaint with the Data Protection Authority if they believe that the processing of their personal data violates the GDPR or Section 1, or Article 2, Part 1. (2) The complaint must include: 1. the designation of the right deemed to have been infringed, 2. to the extent reasonably possible, the designation of the legal entity or body to which the alleged infringement is attributed (the respondent), 3. the facts from which the infringement is derived, 4. the grounds on which the allegation of unlawfulness is based, 5. a request to determine the alleged violation, and 6. the information necessary to assess whether the complaint was filed in a timely manner. (3) A complaint must be accompanied, where applicable, by the underlying request and any response from the respondent. In the event of a complaint, the Data Protection Authority must provide further assistance at the request of the data subject. […]” The relevant provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data, on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), OJ L 119 of May 4, 2016, hereinafter referred to as the GDPR, read as follows, including the heading: The relevant provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) Official Journal L 119 of May 4, 2016, hereinafter referred to as the “GDPR,” are as follows, including the heading: Article 4 Definitions Article 4, Definitions For the purposes of this Regulation, the following terms shall have the following meanings: 1. “personal data” means any information relating to an identified or identifiable natural person (hereinafter referred to as the “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more specific characteristics that reflect the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person; 2. “Processing” means any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transfers, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction; […] 15. “Data concerning health” means personal data relating to the physical or mental health of a natural person, including the provision of health care services, and from which information about that person’s health status can be derived […] Article 5 Principles Governing the Processing of Personal DataArticle 5, Principles Governing the Processing of Personal Data (1) Personal data must a) be processed lawfully, fairly, and in a manner that ensures transparency with regard to the data subject (“lawfulness, fairness, and transparency”); b) be collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes; further processing for archiving purposes in the public interest, for scientific or historical research purposes, or for statistical purposes is not considered incompatible with the original purposes pursuant to paragraph 89(1) (“purpose limitation”); c) be adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed (“data minimisation”); d) be factually accurate and, where necessary, kept up to date; all reasonable measures must be taken to ensure that personal data that is inaccurate in light of the purposes for which it is processed is erased or rectified without delay (“accuracy”); e) be stored in a form that permits identification of data subjects only for as long as is necessary for the purposes for which they are processed; Personal data may be stored for a longer period provided that, subject to the implementation of appropriate technical and organizational measures required by this Regulation to protect the rights and freedoms of the data subject, processed exclusively for archiving purposes in the public interest, or for scientific or historical research purposes, or for statistical purposes in accordance with paragraph 89(1) (“storage limitation”); (f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, through appropriate technical and organizational measures (“Integrity and Confidentiality”); (2) The controller is responsible for compliance with paragraph 1 and must be able to demonstrate such compliance (“accountability”). Article 6 Lawfulness of Processing (1) Processing is lawful only if at least one of the following conditions is met: a) The data subject has given consent to the processing of personal data concerning him or her for one or more specified purposes; b) processing is necessary for the performance of a contract to which the data subject is a party or for the implementation of precontractual measures taken at the data subject’s request; c) processing is necessary for compliance with a legal obligation to which the controller is subject; d) The processing is necessary to protect the vital interests of the data subject or of another natural person; e) The processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller; f) the processing is necessary to protect the legitimate interests of the controller or of a third party, unless the interests or fundamental rights and freedoms of the data subject that require the protection of personal data prevail, in particular where the data subject is a child. Subparagraph 1(f) does not apply to processing carried out by public authorities in the performance of their duties. (2) Member States may maintain or introduce more specific provisions to adapt the application of the rules of this Regulation with respect to processing carried out for the purposes set forth in paragraph 1(c) and (e) by defining specific requirements for such processing and other measures more precisely, to ensure lawfulness and fairness in processing, including for other specific processing situations under Chapter IX.(2) Member States may maintain or introduce more specific provisions to adapt the application of the provisions of this Regulation with regard to processing carried out to fulfill the purposes set forth in paragraph 1(c) and (e) by defining specific requirements for such processing and other measures more precisely, to ensure lawfulness and fairness in processing, including for other specific processing situations set forth in Chapter IX. (3) The legal basis for the processing referred to in paragraph 1(c) and (e) shall be determined by (a) Union law; or (b) the law of the Member States to which the controller is subject. The purpose of the processing must be set out in that legal basis or, with respect to processing pursuant to paragraph 1(e), be necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. This legal basis may contain specific provisions adapting the application of the provisions of this Regulation, including provisions regarding the general conditions governing the lawfulness of processing by the controller, the types of data processed, which data subjects are affected, to which entities and for what purposes personal data may be disclosed, to what purpose limitation they are subject, how long they may be stored, and which processing operations and procedures may be applied, including measures to ensure that processing is carried out in a lawful and fair manner, such as those applicable to other specific processing situations under Chapter IX. Union law or the law of the Member States must pursue an objective in the public interest and be proportionate to the legitimate purpose pursued.The purpose of the processing must be specified in this legal basis or, with respect to processing pursuant to paragraph 1(e), be necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. This legal basis may contain specific provisions to adapt the application of the provisions of this Regulation, including, among other things, provisions regarding the general conditions governing the lawfulness of processing by the controller, the types of data processed, the individuals concerned, the entities to which and the purposes for which personal data may be disclosed, the purpose limitation applied to them, how long they may be stored, and which processing operations and procedures may be applied, including measures to ensure lawfulness and fairness in processing, such as those for other specific processing situations set forth in Chapter IX. Union law or the law of the Member States must pursue an objective in the public interest and be proportionate to the legitimate purpose pursued. (4) Where processing for a purpose other than that for which the personal data were collected is not based on the data subject’s consent or on a provision of Union or Member State law, which constitutes a necessary and proportionate measure in a democratic society to safeguard the objectives referred to in Article 23(1), the controller shall—in order to determine whether the processing for another purpose is compatible with the purpose for which the personal data were originally collected—take into account, among other things, (a) any link between the purposes for which the personal data were collected and the purposes of the intended further processing; (b) the context in which the personal data were collected, in particular regarding the relationship between the data subjects and the controller; (c) the nature of the personal data, in particular whether special categories of personal data are processed pursuant to Article 9 or whether personal data relating to criminal convictions and offenses are processed pursuant to Article 10, (d) the potential consequences of the intended further processing for the data subjects, e) the existence of appropriate safeguards, which may include encryption or pseudonymisation. Article 9 Processing of Special Categories of Personal Data (1) The processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person’s sex life or sexual orientation, is prohibited. (2) Paragraph 1 does not apply in the following cases: (a) The data subject has explicitly consented to the processing of the aforementioned personal data for one or more specified purposes, unless, under Union law or the law of the Member States, the prohibition set forth in paragraph (1) cannot be lifted by the data subject’s consent; b) the processing is necessary for the controller or the data subject to exercise their rights and fulfill their obligations arising from labor law and the law on social security and social protection, to the extent that this is permitted under Union law or the law of the Member States, or under a collective agreement governed by the law of a Member State that provides appropriate safeguards for the fundamental rights and interests of the data subject, (c) the processing is necessary to protect the vital interests of the data subject or of another natural person, and the data subject is physically or legally incapable of giving consent; d) the processing is carried out, on the basis of appropriate safeguards, by a foundation, NGO, or other non-profit organization with political, ideological, religious, or trade-union aims, within the scope of its lawful activities and provided that that the processing relates exclusively to members or former members of the organization, or to persons who maintain regular contact with it in connection with its purposes, and that the personal data is not disclosed to third parties without the consent of the data subjects, e) the processing relates to personal data that the data subject has manifestly made public, f) the processing is necessary for the establishment, exercise, or defense of legal claims or in the course of judicial proceedings by Courts acting within the scope of their judicial functions, g) the processing is necessary for reasons of substantial public interest on the basis of Union law or the law of a Member State, which is proportionate to the objective pursued, respects the essence of the right to data protection, and provides for appropriate and specific measures to safeguard the fundamental rights and interests of the data subject, h) the processing is necessary for the purposes of preventive healthcare or occupational medicine, for assessing the employee’s fitness for work, for medical diagnosis, health or social care or treatment, or for the administration of health or social care systems and services, on the basis of Union law or the law of a Member State, or pursuant to a contract with a health professional, and subject to the conditions and safeguards set forth in paragraph 3; i) the processing is necessary for reasons of public interest in the area of public health, such as protection against serious cross-border threats to health or to ensure high standards of quality and safety in healthcare and with regard to medicinal products and medical devices, is necessary on the basis of Union law or the law of a Member State that provides for appropriate and specific measures to safeguard the rights and freedoms of the data subject, in particular professional secrecy; or (j) the processing is based on Union law or the law of a Member State that is proportionate to the objective pursued, respects the essence of the right to data protection, and provides for appropriate and specific measures to safeguard the fundamental rights and interests of the data subject, is necessary for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes in accordance with article 89(1). (3) The personal data referred to in paragraph 1 may be processed for the purposes set forth in paragraph 2(h) if such data are processed by or under the responsibility of qualified personnel who are subject to a duty of professional secrecy under Union law, the law of a Member State, or the regulations of competent national authorities, or if the processing is carried out by another person who is also subject to a duty of confidentiality under Union law, the law of a Member State, or the rules of national competent authorities. (4) Member States may introduce or maintain additional conditions, including restrictions, to the extent that the processing of genetic, biometric, or data concerning health is concerned. 3.2. On the dismissal of the complaint: On the allocation of roles under data protection law: 3.2.1. The Court of Justice of the European Union (CJEU) has held, with regard to the classification as a controller within the meaning of Article 4(7) of the GDPR, that a controller may also be a public authority or “other body” that, under national law, does not necessarily have to possess legal personality. The controller must be capable of fulfilling the obligations set forth in the GDPR in both factual and legal terms, regardless of whether the entity in question has legal personality or its own legal capacity (see, inter alia, CJEU, Feb. 27, 2025, C-638/23, Office of the Tyrolean Provincial Government, paras. 30, 34, with further references).3.2.1. The Court of Justice of the European Union (CJEU) has held, regarding the classification as a controller within the meaning of Article 4, (7) of the GDPR that a controller may also be a public authority or “other body” that, under national law, is not necessarily required to have legal personality. The controller must be capable of fulfilling the obligations set forth in the GDPR in both factual and legal terms, regardless of whether the entity in question has legal personality or its own legal capacity (see, among other things, CJEU, Feb. 27, 2025, C 638/23, Office of the Tyrolean Provincial Government, paras. 30, 34, with further references). In the present case, this implies the following: 3.2.2. The co-respondent is an organizational unit of the Federal Ministry of National Defense (Training Center of the Austrian Armed Forces) located at 7000 Eisenstadt, Ing. Hans Sylvester-Straße 6. As established, this is an organizational unit of the Federal Ministry of Defense; thus, in accordance with the definition in Article 4(7) of the GDPR, it constitutes “a public authority or ‘other body’ that does not have legal personality under national law.” However, this is not an issue in the present context, as the co-respondent is undoubtedly capable of fulfilling the obligations set forth in the GDPR both in fact and in law. This is against the backdrop that the controller—both in the proceedings before the authority against which the complaint was filed and before the Federal Administrative Court—is represented by officials who are undoubtedly attributable to the competent Federal Minister of Defense as the legal entity. With regard to the authority to represent, it suffices to refer to the current division of responsibilities within the Federal Ministry of Defense (BMLV) (Section 7 of the Federal Ministry Act (BMG)), according to which the authority to handle “data protection matters” within the BMLV lies with the organizational unit of the Central Office known as the “Data Protection Office,” which, among other things, pursuant to § 10(1) and (2) BMG, is responsible for the representation of the Ministry of Defense in data protection matters before the Data Protection Authority and before the Federal Administrative Court. This authority to represent therefore applies both to proceedings in which the Federal Minister of Defense holds the legal status of a “controller” within the meaning of Article 4(7) of the GDPR or § 36(2)(8) of the DSG, as well as to proceedings (such as the present case) in which this legal status is, in exceptional cases, held by other units of the Federal Ministry of Defense (BMLV).As noted, this is an organizational unit of the Federal Ministry of Defense; in accordance with the definition in article 4(7) of the GDPR, it is thus “a public authority or ‘other body’ that does not have legal personality under national law.” However, this is not detrimental in the present context, as the co-party is undoubtedly capable of fulfilling the obligations set forth in the GDPR both in fact and in law. This is against the backdrop that the controller—both in the proceedings before the authority in question and before the Federal Administrative Court—is represented by administrative officials who are undoubtedly attributable to the competent Federal Minister of Defense as the legal entity. With regard to the authority to represent, it suffices to refer to the current division of responsibilities within the Federal Ministry of Defense (Section 7, Federal Ministry Act), according to which the authority to handle “data protection matters” within the BMLV lies with the organizational unit of the Central Office known as the “Data Protection Office,” which, among other things, pursuant to Section 10, paragraphs 1 and 2 of the BMG, includes the representation of the Ministry of Defense in data protection matters before the Data Protection Authority and before the Federal Administrative Court. This authority to represent therefore applies both to proceedings in which the Federal Minister of Defense holds the legal status of a controller within the meaning of article 4(7) GDPR or paragraph 36(2)(8) of the DSG, as well as in proceedings (such as the present case) in which this legal status is, exceptionally, held by other departments of the BMLV. On the merits: 3.2.3. First, regarding the scope of the challenge (Para 9(1) in conjunction with § 27 of the Administrative Court Act (VwGVG)), it must be established that the present appeal against an administrative decision—as evidenced by the clear and unambiguous statement of the complainant—is limited to the ruling of the Data Protection Authority concerning the processing of information related to the complainant’s state of health. Pursuant to Art. 4(15) of the GDPR, “data concerning health” means personal data relating to the physical or mental health of a natural person, including the provision of health care services, and from which information regarding that person’s health status can be derived. According to the settled case law of the CJEU, the concept of data concerning health under Article 9(1) of the GDPR must be interpreted broadly (see, inter alia, CJEU decision of October 4, 2024, Case C-21/23, para. 81). Consequently, there was no reason to challenge the view of the respondent authority that the information at issue in the proceedings—in particular the text passage “[…] my health has deteriorated,” constitutes information regarding the complainant’s state of health and thus constitutes data concerning health within the meaning of Article 4(15) of the GDPR. 3.2.3. First, regarding the scope of the challenge (Section 9, paragraph 1, in conjunction with Section 27, of the Administrative Procedure Act) that the present appeal against the decision—as evidenced by the complainant’s clear and unambiguous statement—is limited to the Data Protection Authority’s ruling concerning the processing of information related to the complainant’s state of health. Pursuant to article 4(15) of the GDPR, “data concerning health” means personal data relating to the physical or mental health of a natural person, including the provision of health care services, and from which information about the person’s health status can be derived. According to the settled case law of the CJEU, the concept of data concerning health under article 9(1) of the GDPR must be interpreted broadly (see, inter alia, CJEU judgment of October 4, 2024, Case C-21/23, para. 81). Consequently, there was no reason to challenge the view of the respondent authority that the information at issue in the proceedings—in particular the text passage “[…] has worsened my state of health,” constitutes information regarding the complainant’s state of health and thus constitutes data concerning health within the meaning of article 4(15) of the GDPR. 3.2.4. It had to be assessed whether the processing of the information (still) at issue in the proceedings, namely a copy of a letter from the complainant to the co-party dated April 29, 2023, which also contains information regarding the complainant’s state of health, which was lawful in light of the requirements of Article 9 of the GDPR. 3.2.4. The issue to be assessed was whether the processing of the information (still) at issue in the proceedings— namely a copy of a letter from the complainant to the co-party dated April 29, 2023, which also contains information regarding the complainant’s state of health, which was lawful in light of the requirements of article 9 of the GDPR. 3.2.5. Pursuant to Article 9(1)(f) of the GDPR, data processing is lawful, among other things, when it is necessary for the establishment, exercise, or defense of legal claims. The processing of personal data for evidentiary purposes in an administrative proceeding—where the statement in question undoubtedly contains information about the complainant within the meaning of Article 9(1) of the GDPR—may, in principle, —provided it is appropriate and necessary—be covered by the legal basis set forth in Article 9(2)(f) of the GDPR (see the judgement of the CJEU of June 17, 2021, in Case C-597/19, para. 106 et seq., with further references). 3.2.5. Pursuant to Article 9(1)(f) of the GDPR, data processing is lawful, among other things, when it is necessary for the establishment, exercise, or defense of legal claims. The processing of personal data for evidentiary purposes in administrative proceedings—as evidenced by the statement in question, which undoubtedly contains information regarding the complainant’s identity within the meaning of article 9(1) GDPR; in principle—provided it is appropriate and necessary—it may be covered by the legal basis set forth in article 9(2)(f) of the GDPR (see the judgement of the CJEU of June 17, 2021, in Case C-597/19, para. 106 et seq., with further references). The legal basis set forth in Article 9(2)(f) of the GDPR constitutes, for the special categories of data referred to in paragraph 1, a specific case of the general legal basis of legitimate interest within the meaning of Article 6(1)(f) of the GDPR. The term “legal claims” is to be understood broadly and encompasses claims under both public and private law. The decisive factor is that a legal dispute exists. The Art of the legal proceedings initiated, however, is irrelevant. “Necessary” means that, without the data, asserting the claim or defending against it would be impossible or significantly more difficult (see Supreme Court decision of August 24, 2022, 7Ob121/22b, para. 22 et seq.).The grounds for processing set forth in Article 9(2)(f) of the GDPR constitute, for the special categories of data mentioned in paragraph 1, a specific case of the general grounds for processing based on legitimate interests within the meaning of Article 6(1)(f) of the GDPR. The term “legal claims” is to be understood broadly and encompasses claims under both public and private law. The decision is that a legal dispute exists. The type of legal action taken, however, is irrelevant. “Necessary” means that, without the data, asserting the claim or defending against it would be impossible or significantly more difficult (see Supreme Court decision of August 24, 2022, 7Ob121/22b, para. 22 et seq.). With regard to the necessity of processing sensitive data required by Article 9(2)(f), given the important role this exception plays in the enforceability of claims under the rule of law, the standard applied should not be overly strict. If the Court deems a party’s submission of special categories of personal data to be irrelevant, this does not in all circumstances simultaneously constitute a violation of Article 9. However, if sensitive data is disclosed arbitrarily and intentionally without any connection to the specific case in dispute, the party cannot invoke the exception under Article 9(2)(f) of the GDPR (see Jahnel, Commentary on the General Data Protection Regulation, Art. 9 GDPR, as of Dec. 1, 2020, para. 88, rdb.at).With regard to the requirement for the processing of sensitive data set forth in article 9(2)(f), given the important role this exception plays in the enforceability of claims under the rule of law, the standard applied should not be overly strict. If the Court deems a party’s submission of special categories of personal data to be irrelevant, this does not in all circumstances simultaneously constitute a violation of Article 9. However, if sensitive data is disclosed arbitrarily and intentionally without any connection to the specific case in dispute, the party cannot invoke the exception under article 9(2)(f) of the GDPR (see Jahnel, Commentary on the General Data Protection Regulation, article 9, GDPR, as of Dec. 1, 2020, margin note 88, rdb.at). 3.1.3.4. Insofar as the complainant argues in this regard that it is conceptually impossible for his data concerning health to have any bearing on the investigation into whether a person disclosed his non-final disciplinary finding, he first overlooks the fact that the purpose of the investigative proceedings in the XXXX case before the Data Protection Authority was also to determine whether the complainant’s numerous submissions were to be considered excessive within the meaning of Art. 57(4) of the GDPR. In this regard, from the perspective of the adjudicating Court, it was by no means inconceivable—but rather obvious—that, from an ex ante perspective, all information regarding the various legal disputes between the parties to the proceedings was deemed relevant to the presentation of the facts by the authority under investigation and was therefore also transmitted to it. This is particularly true in light of the fact that legal disputes have existed between the parties for years, most of which were initiated by the complainant. Given the sheer volume of—and, for the most part, thematically overlapping — legal disputes—it could not have come as a surprise to the complainant that the co-party would also use the statements made therein to defend its legal position in the present proceedings, in order to provide a comprehensive chronological overview of the complainant’s numerous motions and statements. In this context, it should be noted in particular that para 9(2)(f) of the GDPR is intended to ensure the enforcement of the right to an effective remedy and to a fair trial within the meaning of Article 47 of the CFR. However, from the perspective of this Court, it also necessarily follows that the threshold for determining when data is no longer considered relevant to the proceedings must be set very high. Otherwise, parties to a dispute would be deterred from presenting comprehensive arguments for fear of a possible data protection violation, which would consequently restrict Article 47 of the CFR and, in turn, undermine the spirit and purpose of Article 9(2)(f) of the GDPR. Consistent with this, the aforementioned commentary literature, which states that the necessity of data processing within the meaning of Article 9(2)(f) of the GDPR ceases to exist only when data that has no connection whatsoever to the subject matter of the dispute is disclosed arbitrarily and intentionally. Since, from an ex ante perspective, it could by no means be ruled out that the complainant’s brief dated April 29, 2023, together with the data concerning health contained therein, was—in the proceedings before the respondent authority regarding XXXX (at least) in an abstract and conceivable manner to substantiate the legal position of the co-party, its transfer to the respondent authority by the co-party does not constitute a violation of the processing principles and grounds for lawfulness set forth in Art. 5(1), 6(1), and 9(1) and (2) of the GDPR. 3.1.3.4. Insofar as the complainant argues in this regard that it is inconceivable that the data concerning his health could have any bearing on the investigation into whether a person disclosed his non-final disciplinary decision, he first overlooks the fact that the purpose of the preliminary investigation in the proceedings before the Data Protection Authority under Roman 40 was also to determine whether the complainant’s numerous submissions were to be considered excessive within the meaning of article 57(4) of the GDPR. In this regard, from the perspective of the adjudicating Court, it was by no means inconceivable—but rather obvious—that, from an ex ante perspective, all information regarding the various legal disputes between the parties to the proceedings was deemed relevant to the presentation of the facts by the authority under scrutiny and was therefore also transmitted to it. This is particularly true in light of the fact that legal disputes have existed between the parties for years, most of which were initiated by the complainant. Given the sheer volume of these disputes—most of which also overlap thematically — legal disputes, it could not have come as a surprise to the complainant that the co-party would also use the statements made therein to defend its legal position in the present proceedings, in order to provide a comprehensive chronological overview of the complainant’s numerous motions and statements. In this context, it should be noted in particular that article 9, paragraph 2, letter f of the GDPR is intended to ensure the enforcement of the right to an effective remedy and to a fair trial within the meaning of article 47 of the CFR. However, in the view of this Court, it also necessarily follows that the threshold for when data is no longer considered relevant to the proceedings must be set very high. Otherwise, parties to a dispute would be deterred from presenting comprehensive arguments out of fear of a potential data protection violation, which would consequently restrict Article 47 of the CFR and, as a result, undermine the meaning and purpose of Article 9(2)(f) of the GDPR. Consistent with this, the aforementioned scholarly commentary also indicates that the necessity of data processing within the meaning of Article 9(2)(f) GDPR is no longer met only when data that is completely unrelated to the matter in dispute is disclosed arbitrarily and intentionally. Since, from an ex ante perspective, it could by no means be ruled out that the complainant’s brief dated April 29, 2023, together with the data concerning health contained therein, was (at least) abstractly and conceivably capable of supporting the legal position of the co-party in the proceedings before the respondent authority, (at least) abstractly and conceivably suitable for substantiating the legal position of the co-party, its transmission to the respondent authority by the co-party does not constitute a violation of the processing principles and grounds for authorization set forth in articles 5(1), 6(1), and 9(1) and (2) of the GDPR. Furthermore, the respondent authority is a body bound by a duty of confidentiality, thereby ensuring enhanced protection of any health-related information pertaining to the complainant. Furthermore, the respondent’s view must be upheld, namely that the information at issue here was generated by the complainant himself and disclosed to the co-party, which significantly reduces the need for its protection. Taken as a whole, therefore, the co-party’s interest in the transfer of the data to defend its legal position clearly outweighs the complainant’s interest in confidentiality. The processing of the disputed information is therefore lawful pursuant to Article 6(1)(f) in conjunction with Article 9(2)(f) of the GDPR.Furthermore, the respondent authority is a body bound by a duty of confidentiality, which ensures enhanced protection of any health-related information pertaining to the complainant. Furthermore, the respondent authority’s view must be upheld, namely that the information at issue here was generated by the complainant himself and disclosed to the other party to the proceedings, which significantly reduces the need for its protection. Taken as a whole, therefore, the co-party’s interest in the transfer of the data to defend its legal position clearly outweighs the complainant’s interest in confidentiality. The processing of the disputed information is thus lawful pursuant to Article 6(1)(f), in conjunction with Article 9(2)(f), of the GDPR. 3.1.3.6. Finally, insofar as the complainant further objects that the transfer of the data concerning health to the Data Protection Office was already unlawful, reference must be made to the role of the Data Protection Office as already explained above, according to which it performs the data protection-related tasks of the co-party. The representation of the co-party before the authority in question is based on a statutory foundation (Section 7 of the Federal Ministry of the Interior Act), and in this regard as well, one can concur with the respondent authority’s legal opinion that this also justifies all data processing that is (conceivably) necessary for the performance of these tasks. For the reasons already explained above, it can be affirmed beyond doubt that the data processing in question was necessary for the representation of the co-party before the respondent authority and thus for the Data Protection Office to perform its duties. The data processing—specifically, the transfer of data concerning health to the Data Protection Office—was therefore lawful pursuant to Art. 6(1)(e) in conjunction with Art. 9(2)(g) of the GDPR. 3.1.3.6. Finally, insofar as the complainant further objects that the transfer of data concerning health to the Data Protection Office was unlawful, reference must be made to the role of the Data Protection Office as already explained above, according to which it performs the data protection-related duties of the co-party. The representation of the co-party before the respondent authority is based on a statutory provision (Section 7, BMG), and in this regard as well, the legal opinion of the responding authority can be endorsed, namely that this also justifies all data processing that is (conceivably) necessary for the performance of these tasks. For the reasons already explained above, it can be affirmed beyond doubt that the data processing in question was necessary for the representation of the co-party before the respondent authority and thus for the Data Protection Office to perform its duties. The data processing—specifically, the transfer of data concerning health to the Data Protection Office—was therefore lawful pursuant to Article 6(1)(e) in conjunction with Article 9(2)(g) of the GDPR. The complaint was therefore dismissed as unfounded. 3.1.3.7. Regarding the Waiver of an Oral Hearing: Pursuant to § 24(1) of the Administrative Court Act (VwGVG), the Administrative Court must conduct a public oral hearing upon request or, if it deems it necessary, on its own initiative.Pursuant to paragraph 24(1) of the VwGVG, the Administrative Court must conduct a public oral hearing upon request or, if it deems it necessary, on its own motion. Pursuant to § 24(4) VwGVG, unless otherwise provided by federal or state law, the administrative court may, regardless of a party’s request, dispense with a hearing if the case file indicates that an oral hearing is unlikely to further clarify the matter, and neither Article 6(1) of the ECHR nor Article 47 of the CFR precludes the omission of a hearing. Pursuant to paragraph 24(4) of the VwGVG—unless otherwise provided by federal or state law— – the Administrative Court may, regardless of a party’s motion, dispense with an oral hearing if the case file indicates that an oral hearing is unlikely to provide further clarification of the matter, and neither article 6, paragraph 1, of the ECHR nor article 47 of the CFR preclude the omission of the oral hearing. In the present case, the facts were clarified by the record. It was not necessary to consider further evidence to clarify the facts. 3.2. Regarding Point B) Inadmissibility of the Appeal: Pursuant to § 25a(1) of the Administrative Court Act (VwGG), the Administrative Court must state in the operative part of its judgment or order whether the appeal is admissible under Article 133(4) of the Federal Constitutional Act (B-VG). The ruling must be briefly justified. Pursuant to Section 25a(1) of the VwGG, the Administrative Court must state in the operative part of its judgment or order whether the appeal is admissible under Article 133(4) of the B-VG. The ruling must be briefly justified. The present decision does not depend on the resolution of a legal issue of fundamental significance. There is no lack of case law from the Administrative Court, nor does the present decision deviate from the case law of the Administrative Court; furthermore, the relevant case law of the Administrative Court is not to be regarded as inconsistent. Nor are there any other indications that the legal issues to be resolved are of fundamental importance. When assessing whether a specific data processing activity can be considered justified in light of Art. 6(1)(f) [or Art. 9(2)(f)] of the GDPR, this involves a case-by-case balancing of interests that requires an assessment of the specific circumstances, taking into account all relevant factors. When assessing whether a specific data processing operation can be considered justified in light of Article 6(1)(f) [or Article 9(2)(f)] GDPR, this involves a case-by-case balancing of interests that requires an assessment in each individual case, taking into account all relevant circumstances. As with other case-by-case assessments, a fundamental legal question within the meaning of Art. 133(4) B-VG only then exists if this assessment was made in an unreasonable manner that undermines legal certainty—that is, in a grossly erroneous manner (see VwGH 7/24/2024, Ra 2024/04/0376, with further references). As with other case-by-case assessments, a question of principle within the meaning of Article 133, paragraph 4, B-VG only if this assessment was made in an unreasonable manner that undermines legal certainty—that is, if it was grossly erroneous (see VwGH July 24, 2024, Ra 2024/04/0376, with further references).

---
Generated by overview.legal · https://overview.legal/posts/353789 · 2026-09-09
